Skip to content

← Pricing / Starter

Starter - 99 EUR

A single automated, read-only scan of your public website. 15 passive HTTP/TLS checks. PDF summary emailed within 24 hours.

What the automated scan checks (honest scope)

  1. HTTPS redirect enforcement
  2. HSTS header (+ preload flag when present)
  3. Content-Security-Policy presence
  4. X-Frame-Options / CSP frame-ancestors
  5. X-Content-Type-Options (nosniff)
  6. Referrer-Policy
  7. Permissions-Policy
  8. Cookie flags (HttpOnly / Secure / SameSite) on Set-Cookie headers
  9. TLS version signals available at the edge
  10. Server / X-Powered-By banner leakage
  11. Mixed content in HTML
  12. Subresource Integrity on external scripts
  13. robots.txt presence
  14. .well-known/security.txt presence
  15. Basic technology fingerprint (CMS/library hints in HTML/headers)

Not included in Starter automated scan: open port scans, DNSSEC/SPF/DKIM/DMARC deep DNS, CVE databases, HaveIBeenPwned/breach lookups, subdomain enumeration, cloud bucket discovery, or authenticated testing. Those belong in Standard/Premium human engagements.

What you do NOT get

If you need any of the above, the Standard tier starts at 799 EUR and includes 8 hours of engineer review.

Order now - EUR 99

Card checkout via Stripe. Scan starts within 24 hours of payment clearing. PDF emailed to the address you use at checkout.

powered by Stripe · VAT handled automatically · 14-day refund window

What happens next

  1. Stripe confirms payment (Apple Pay / Google Pay / card).
  2. Scoping email reaches you within 60 seconds.
  3. Reply with any authentication or scope notes (optional).
  4. Scan runs within 24 hours. PDF delivered to the email on your order.

Refund policy

If the scan cannot reach your domain (DNS misconfiguration, rate limit, geo-block), you get a full refund. If findings are disputed, we re-run the specific check at no charge. Once the PDF is delivered, the engagement is considered complete.

reading as
consumerpro